CVE-2020-5362
Dell Client Consumer and Commercial platforms include an improper authorization vulnerability in the Dell Manageability interface for which an unauthorized actor, with local system access with OS administrator privileges, could bypass the BIOS…
Does this matter?
Lower severity and a low EPSS score (0.29%). Track it; it rarely justifies an emergency change on its own.
Description
Dell Client Consumer and Commercial platforms include an improper authorization vulnerability in the Dell Manageability interface for which an unauthorized actor, with local system access with OS administrator privileges, could bypass the BIOS Administrator authentication to restore BIOS Setup configuration to default values.
- CVSS 3.1
- 4.4 MEDIUMCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N
- EPSS
- 0.29% probability · 22th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-285, CWE-862
- Affected
- dell/chengming 3967 firmware · dell/chengming 3977 firmware · dell/chengming 3980 firmware · dell/chengming 3988 firmware · dell/chengming 3990 firmware · dell/chengming 3991 firmware · dell/g3 15 3500 firmware · dell/g3 15 3590 firmware · dell/g3 3579 firmware · dell/g3 3779 firmware · dell/g5 15 5500 firmware · dell/g5 15 5590 firmware · dell/g5 5587 firmware · dell/g7 15 7590 firmware · dell/g7 17 7790 firmware · dell/g7 7588 firmware · dell/embedded box pc 5000 firmware · dell/g5 5090 firmware · dell/inspiron 11 2-in-1 3153 firmware · dell/inspiron 11 2-in-1 3158 firmware · +40 more
- Source
- security_alert@emc.com
References
- https://www.dell.com/support/article/SLN321726Vendor Advisory
- https://www.dell.com/support/article/SLN321726Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.